Threat Detection & Response Analyst

1 week, 1 day ago
Contract
Senior
Cybersecurity
Skyepoint Decisions

Skyepoint Decisions

Skyepoint Decisions specializes in providing comprehensive IT solutions for the federal government, focusing on cybersecurity architecture, critical infrastructure operations, and applications development and maintenance to support a secure and mobile ...

Internet Software & Services
51-250
Founded 2009

Description

  • Conduct proactive threat hunting using intelligence-driven and hypothesis-based methods.
  • Analyze threat actor tactics, techniques, and procedures to identify potential compromise.
  • Map adversary behaviors and indicators to the MITRE ATT&CK framework.
  • Monitor security tools, dashboards, and alerts for suspicious activity and threats.
  • Analyze endpoint, network, cloud, and security monitoring data.
  • Triage security alerts to determine validity, severity, and impact.
  • Investigate cybersecurity incidents, security events, and anomalous activity.
  • Perform forensic review of logs, alerts, and system data to determine root cause and scope.
  • Correlate information from multiple security tools and data sources.
  • Document findings, recommendations, and lessons learned, and support post-incident reviews and corrective actions.
  • Support RMF activities, risk assessments, POA&M development, continuous monitoring, and cybersecurity governance processes.
  • Assist with audit readiness and security assessment activities as needed.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Minimum 5 years of experience in cybersecurity operations, threat detection, security monitoring, incident response, or SOC environments.
  • Experience applying MITRE ATT&CK techniques and adversary behaviors during investigations, threat hunting, or detection activities.
  • Experience investigating cybersecurity incidents and analyzing security events.
  • Knowledge of cyber threat TTPs, SOC processes, incident response methodologies, network security concepts, and endpoint security technologies.
  • Familiarity with NIST RMF (SP 800-37), NIST SP 800-53 Rev. 5, FISMA, and federal cybersecurity requirements.
  • Strong analytical, troubleshooting, and communication skills.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Public Trust.
  • Preferred certifications include Security+, CySA+, GCIH, GCIA, CISSP, CEH, GSEC, CASP+, or CISM.
  • Experience supporting HHS or other federal civilian agencies.
  • Experience working in a SOC environment.
  • Knowledge of MITRE ATT&CK Framework methodologies.
  • Experience supporting cloud security operations in Azure, AWS, or Google Cloud.
  • Familiarity with Continuous Diagnostics and Mitigation (CDM) initiatives.
  • Experience protecting healthcare, biomedical, or research-focused environments.

Benefits

  • Salary range of $95,000 to $110,000.
  • Certification incentive program.
  • PTO.
  • Floating federal holiday options.
  • Health insurance options including HMO and High Deductible plans with HSAs.
  • Flexible Spending Accounts (FSAs).
  • Dental, vision, short-term disability, long-term disability, and life insurance.
  • 401(k) match.
  • Flexible work environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

1 week, 1 day ago

Cyber Detection and Response Analyst, Asia Pacific

Control Risks 1K-5K Professional Services

Cyber Detection and Response Analyst at a global security team, supporting 24/7 threat detection, investigation, and response across a client environment.

AWS Azure CrowdStrike Cybersecurity GCP SIEM Splunk
2 weeks, 5 days ago

Fractional Cyber Security Analyst (Advisor Network)

Arootah 11-50 Professional Services

Arootah is seeking an experienced Cybersecurity Analyst to join its advisor network and support hedge fund and family office clients on project-based cybersecurity engagements.

Active Directory Azure Cybersecurity Encryption Network Security Penetration Testing SQL Windows Server
3 weeks, 1 day ago

Surveillance Officer

Prevail Partners 11-50 Professional Services

Prevail Partners is seeking experienced Surveillance Officers to support an Ultra High Net Worth client through discreet protective surveillance operations within a specialist security programme.

4 weeks, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers